CVE-2005-3750
- EPSS 7.62%
- Published 22.11.2005 19:03:00
- Last modified 03.04.2025 01:03:51
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that another product provides in a command line argument when launching Opera.
- EPSS 0.35%
- Published 21.11.2005 11:03:00
- Last modified 03.04.2025 01:03:51
Opera Web Browser 8.50 and 8.0 through 8.0.2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site.
- EPSS 0.46%
- Published 26.09.2005 19:03:00
- Last modified 03.04.2025 01:03:51
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."
- EPSS 0.44%
- Published 22.09.2005 10:03:00
- Last modified 03.04.2025 01:03:51
Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."
- EPSS 1.12%
- Published 21.09.2005 20:03:00
- Last modified 03.04.2025 01:03:51
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
CVE-2005-3007
- EPSS 1.45%
- Published 21.09.2005 20:03:00
- Last modified 03.04.2025 01:03:51
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.
- EPSS 1.34%
- Published 01.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executi...
CVE-2005-2406
- EPSS 0.49%
- Published 01.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.
CVE-2005-2407
- EPSS 1.11%
- Published 01.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the "Run" button, aka "link hijack...
- EPSS 1.86%
- Published 19.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.